• My Weekly RoundUp #118

    This week i was very busy at work, so i wasn't able to collect a lot of news. However, the few news i've read are really juicy stuff: for example, E.T. is back! So, let's talk about Mixcloud, Signal, unsecure… read more »
  • Michael Gillespie, the Ransomware Superhero

    Despite in the last months the infection number is decreasing (source), finding yourself with personal or corporate files blocked by a ransomware attack is a widespread drama. But luckily there are little-known people who work to get out of trouble… read more »
  • What's new in Volatility 3?

    In last years, the way that operating systems are developed, deployed, and maintained evolved quickly.Similarly, the skillsets of memory analysts and their preferred work flows have changed to meet a world with increasingly large volumes of complex data. In order… read more »
  • Flan Scan: a lightweight network vulnerability scanner by Cloudflare

    Cloudflare released a new open source vulnerability scanner that uses Nmap results to generate more complex vulnerability reports. The tool, called Flan Scan, is a Python script developed in order to fill-the-gap between “industry standard” scanners and Cloudflare's compliance scans… read more »
  • CVE-2019-14271: a Docker 'cp' container escape vulnerability

    Researchers from Paloalto Networks' Unit42 discovered an issue in the implementation of the Docker cp command that can lead to full container escape if exploited by an attacker. This would allow an attacker full root control of the host and… read more »
  • My Weekly RoundUp #117

    Sure, the main event of this week was the launch of Tesla Cybertruck, but I've also other interesting topics, for example Wordpress sites under attack, Roboto Linux botnets, Mac malware related to Lazarus and Nextcry, a ransonware that targets Nextcloud… read more »
  • A new Android vulnerability (CVE-2019-2234) allows attackers to hijack Camera App

    Researchers from Checkmarx Security Research Team has discovered and disclosed a vulnerability [2] in Android camera app that may allows a malicious app to bypass camera access permissions. How it works? Android camera applications usually store their photos and videos… read more »
  • New WhatsApp vulnerability allows remote command execution using a crafted MP4 file

    Update your client ASAP! In October, a double-free vulnerability was disclosed in WhatsApp messenger: this flaw could be triggered through the sending of a crafted .GIF file and, if exploited, could result in the remote execution of code. The vulnerability… read more »